Question 1
Q1A financial institution requires strict Zero Trust implementation for their internal network. They need to ensure that access to the 'Core-Banking' zone is restricted not just by user identity, but also by the specific device being used, ensuring no unmanaged devices can connect. The solution must persist even if the device IP changes. Which combination of Palo Alto Networks features should the architect design into the security policy?
Show answer & explanation
Correct answer: B
Device-ID provides persistent identification of a device regardless of network changes (like IP address) and allows policy enforcement based on the specific device itself, not just the user or IP. Combining User-ID (who) with Device-ID (which machine) creates the required precise Zero Trust policy control.